Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

when conditionals in RHEL STIG roles fail with ansible-core 2.19+

オープン
#15,005 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 3 日以内に返信

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
ansible
領域
devops, security

調査の方向性

redhatofficial.rhel9_stig および redhatofficial.rhel10_stig roles 用に生成された tasks/main.yml から始め、1957 行付近で報告された失敗を含めて、AIDE と audit privileged-functions の条件がどのように生成されるかを調査します。RHEL 9 または RHEL 10 上で ansible-core 2.19+ を使用して roles を実行します。membership tests がブール値として評価され、条件評価の失敗が発生しなければ完了です。

索引モデルが issue の本文から書いたものです。

説明

Ansible RHEL triaged
Description of problem:

Some Ansible when conditionals contain an additional pair of quotes around membership tests. This causes the membership test to be evaluated as a string literal instead of a boolean expression.

Ansible-core 2.19+ requires conditional results to be boolean and the affected tasks fail during conditional evaluation.

The issue is observable in redhatofficial.rhel9_stig and redhatofficial.rhel10_stig roles.

For example, the AIDE condition contains:
find_rules_groups_results is not skipped and "'aide' in ansible_facts.packages"
instead of:
find_rules_groups_results is not skipped and 'aide' in ansible_facts.packages

The audit privileged-functions condition similarly contains:
('"auditd.service" in ansible_facts.services' or '"augenrules.service" in ansible_facts.services')
instead of:
("auditd.service" in ansible_facts.services or "augenrules.service" in ansible_facts.services)

Operating System Version:

RHEL 9 / RHEL 10

Actual Results:

The role fails during conditional evaluation under ansible-core 2.19+ because the quoted membership expression produces a non-boolean result.
[ERROR]: Task failed: Conditional result (True) was derived from value of type 'str' at '/home/app/.ansible/roles/redhatofficial.rhel10_stig/tasks/main.yml:1957:5'. Conditionals must have a boolean result.

Expected Results:

Generate the membership tests as boolean expressions without the additional quoting, allowing the RHEL 9 and RHEL 10 STIG roles to run with ansible-core 2.19+.

主要言語
Shell
スター
2.8k
フォーク
835
平均マージ
4日 6時間
マージ済み PR(30日)
44

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

ComplianceAsCode/content のほかの issue

ComplianceAsCode/content の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。